Server side cross-site scripting In dolibarr/dolibarr
Description
Cross Site Scripting vulnerability in Dolibarr ERP CRM Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 17.0.1 |
Aliases
1. 2. 3. 4.
References
1. 2.